diff --git a/04-ISSUES/113-the-object-stores-images-were-withdrawn-upstream/00-report.md b/04-ISSUES/113-the-object-stores-images-were-withdrawn-upstream/00-report.md index 36a24d3..7573c96 100644 --- a/04-ISSUES/113-the-object-stores-images-were-withdrawn-upstream/00-report.md +++ b/04-ISSUES/113-the-object-stores-images-were-withdrawn-upstream/00-report.md @@ -75,9 +75,19 @@ necessary. The instance is harmless; the standing condition is not. 1. **No new node can ever provision this module.** Every node that does not already hold the - images is permanently unable to obtain them. The mesh's claim that a node can be rebuilt from - its declarations is false for this module, and will be false the same way for any module whose + images is permanently unable to obtain them, and the same will be true of any module whose upstream withdraws an image. + + This is the failure mode of a deliberate design choice, which is why it is worth recording + rather than patching. The foundation design chooses **references over payload** — *"the bundle + names images by digest and the host fetches them"* — on the stated grounds that + *"reproducibility comes from pinning the identity of a thing rather than carrying its bytes"* + ([to-be 07](../../03-DESIGN/01-to-be/07-the-foundation.md)). That reasoning is sound. It holds + only while a pinned identity stays **resolvable**, and nothing in the mesh's control guarantees + that for an image in somebody else's registry. The passage is about + the foundation bundle, and this module is not in it; but the pattern — pin the identity, fetch + the bytes on demand — is how every module gets its third-party images, so the exposure is + general even though the sentence is local. 2. **The pinned release is permanently unpatched.** It is four and a half years old, upstream is archived, and no security fix will ever reach it. 3. **Nothing detects this class of failure.** The condition is invisible until a node without the @@ -94,8 +104,9 @@ mesh currently learns it has lost one only by trying to use it. - Should the mesh **hold** the images it depends on — mirroring third-party images into its own registry at adoption, so a module's installability does not depend on an upstream's continued - goodwill? That is the fix that generalises, and it costs storage and a policy about what to - mirror. + goodwill? That is the fix that generalises. It costs storage and a policy about what to mirror, + and it is a deliberate move **away** from references-over-payload for third-party images + specifically — so it should be decided as such, not smuggled in as a fix. - Should a module's images be pinned **by digest** rather than by tag? It makes the artifact exact and auditable, but does nothing about withdrawal — a deleted digest is just as gone. - What **checks** that every module in the catalogue is still obtainable from a node that holds